feat: add wildcard pattern support for logging header capture (e.g. x-custom-*) - #3958
Conversation
📝 WalkthroughWalkthroughAdds wildcard pattern matching for configured logging headers (exact, ChangesLogging Header Wildcard Patterns
Model Catalog UI Text
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Warning There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure. 🔧 golangci-lint (2.12.2)level=error msg="[linters_context] typechecking error: pattern ./...: directory prefix . does not contain main module or its selected dependencies" Comment |
x-custom-*)
This stack of pull requests is managed by Graphite. Learn more about stacking. |
30c135f to
f67aaef
Compare
Confidence Score: 5/5Safe to merge — the change is well-scoped, the matching logic is correct, and the wildcard behaviour is consistent with how header keys are stored. The matching helper covers all three code paths correctly, header lowercasing is handled consistently between the transport layer and the new pattern loop, the UI preserves E2E test identifiers, and no existing behaviour is regressed. No files require special attention. Important Files Changed
Reviews (2): Last reviewed commit: "feat: support wildcard on request header..." | Re-trigger Greptile |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@ui/app/workspace/config/views/loggingView.tsx`:
- Around line 237-240: Add a short security note to the header capture help text
in loggingView.tsx warning that wildcard patterns (especially "*" ) will capture
all headers including sensitive ones like Authorization/API keys; update the JSX
text block that currently describes comma-separated and wildcard header patterns
(the help text string around "Comma-separated list of request headers to
capture...") to append a concise sentence such as "Note: '*' captures all
headers — review for sensitive data before enabling." so users are explicitly
warned about possible exposure.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 39dedea0-569f-421a-9b4e-6087e324299b
📒 Files selected for processing (2)
plugins/logging/main.goui/app/workspace/config/views/loggingView.tsx
f67aaef to
d26c778
Compare
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@plugins/logging/main.go`:
- Around line 483-488: When iterating allHeaders in the wildcard scan (the loop
over for hKey, hVal := range allHeaders where
loggingHeaderMatchesPattern(pattern, hKey) is checked) skip any header whose
name starts with the normalized prefix "x-bf-lh-" so those headers are not added
again into metadata; implement a guard before creating/setting metadata that
continues the loop if strings.HasPrefix(strings.ToLower(hKey), "x-bf-lh-") (or
equivalent) to avoid duplicating headers already handled by the dedicated
normalized block.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: 2ea59c8f-80e6-44ef-87a8-b8fe4c8f685e
📒 Files selected for processing (3)
plugins/logging/main.goui/app/workspace/config/views/loggingView.tsxui/app/workspace/model-catalog/views/attributesTab.tsx
Merge activity
|
…x-custom-*`) (#3958) ## Summary Adds wildcard pattern support to the logging headers configuration, allowing users to capture groups of headers by prefix (e.g. `x-custom-*`) or all headers at once using `*`, rather than only exact header name matches. ## Changes - Introduced `loggingHeaderMatchesPattern` to handle exact matches, trailing wildcard (`x-custom-*`), and bare wildcard (`*`) patterns against incoming header names - Updated `captureLoggingHeaders` to iterate over all request headers and match each against configured patterns, replacing the previous single-key lookup - Updated the UI description and placeholder text to document wildcard support ## Type of change - [ ] Bug fix - [x] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI ## Affected areas - [ ] Core (Go) - [ ] Transports (HTTP) - [ ] Providers/Integrations - [x] Plugins - [x] UI (React) - [ ] Docs ## How to test Configure logging headers with a wildcard pattern such as `x-custom-*` or `*` and send requests with matching headers. Verify that the captured headers appear in the `metadata` field of log entries. ```sh go test ./plugins/logging/... cd ui pnpm i || npm i pnpm test || npm test pnpm build || npm run build ``` ## Screenshots/Recordings **Before:** Placeholder showed `X-Tenant-ID, X-Request-Source, X-Correlation-ID` with no mention of wildcard support. **After:** Placeholder shows `X-Tenant-ID, X-Request-Source, x-custom-*` and the description explains exact names, prefix wildcards, and the bare `*` option. ## Breaking changes - [ ] Yes - [x] No ## Related issues ## Security considerations Using `*` as a logging header pattern will capture all request headers, which may include sensitive values such as `Authorization` or session tokens. Users should be aware of the PII and secrets exposure risk when enabling broad wildcard patterns, and ensure log storage is appropriately access-controlled. ## Checklist - [ ] I read `docs/contributing/README.md` and followed the guidelines - [ ] I added/updated tests where appropriate - [ ] I updated documentation where needed - [ ] I verified builds succeed (Go and UI) - [ ] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Logging headers configuration now supports wildcard patterns (e.g., `x-custom-*`, `*`) as well as exact names. * Request headers matching configured patterns are automatically captured as metadata, with support for bare (`*`) and prefix (`prefix*`) wildcards. * Headers with the `x-bf-lh-` prefix are always captured. * **Documentation** * Clarified logging configuration help text and updated placeholder examples for header input. * Shortened Models section copy to “Attach descriptions and tags to specific models.” <!-- end of auto-generated comment: release notes by coderabbit.ai -->
…x-custom-*`) (#3958) ## Summary Adds wildcard pattern support to the logging headers configuration, allowing users to capture groups of headers by prefix (e.g. `x-custom-*`) or all headers at once using `*`, rather than only exact header name matches. ## Changes - Introduced `loggingHeaderMatchesPattern` to handle exact matches, trailing wildcard (`x-custom-*`), and bare wildcard (`*`) patterns against incoming header names - Updated `captureLoggingHeaders` to iterate over all request headers and match each against configured patterns, replacing the previous single-key lookup - Updated the UI description and placeholder text to document wildcard support ## Type of change - [ ] Bug fix - [x] Feature - [ ] Refactor - [ ] Documentation - [ ] Chore/CI ## Affected areas - [ ] Core (Go) - [ ] Transports (HTTP) - [ ] Providers/Integrations - [x] Plugins - [x] UI (React) - [ ] Docs ## How to test Configure logging headers with a wildcard pattern such as `x-custom-*` or `*` and send requests with matching headers. Verify that the captured headers appear in the `metadata` field of log entries. ```sh go test ./plugins/logging/... cd ui pnpm i || npm i pnpm test || npm test pnpm build || npm run build ``` ## Screenshots/Recordings **Before:** Placeholder showed `X-Tenant-ID, X-Request-Source, X-Correlation-ID` with no mention of wildcard support. **After:** Placeholder shows `X-Tenant-ID, X-Request-Source, x-custom-*` and the description explains exact names, prefix wildcards, and the bare `*` option. ## Breaking changes - [ ] Yes - [x] No ## Related issues ## Security considerations Using `*` as a logging header pattern will capture all request headers, which may include sensitive values such as `Authorization` or session tokens. Users should be aware of the PII and secrets exposure risk when enabling broad wildcard patterns, and ensure log storage is appropriately access-controlled. ## Checklist - [ ] I read `docs/contributing/README.md` and followed the guidelines - [ ] I added/updated tests where appropriate - [ ] I updated documentation where needed - [ ] I verified builds succeed (Go and UI) - [ ] I verified the CI pipeline passes locally if applicable <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Logging headers configuration now supports wildcard patterns (e.g., `x-custom-*`, `*`) as well as exact names. * Request headers matching configured patterns are automatically captured as metadata, with support for bare (`*`) and prefix (`prefix*`) wildcards. * Headers with the `x-bf-lh-` prefix are always captured. * **Documentation** * Clarified logging configuration help text and updated placeholder examples for header input. * Shortened Models section copy to “Attach descriptions and tags to specific models.” <!-- end of auto-generated comment: release notes by coderabbit.ai -->
## ✨ Features - **OpenAI Compaction** — Added OpenAI conversation compaction support across core, framework, logging, and the API surface (#4053) - **Multi-Customer & Org Hierarchy** — Logs and usage tracking now support multiple customers, teams, and business units, including business unit CRUD, team assignment, and governance endpoints in the OpenAPI spec (#4066, #4041, #4082) - **Provider-Level Governance** — Budgets & limits are now scope-aware and can be applied at the virtual-key top level and per provider, wired from the model configs table, with UI filters for scope and providers (#3938, #3937, #3939, #3981, #3962) - **Customer Budgets** — Customers support multiple budgets and `calendar_aligned` budget windows (#3998, #3997) - **Virtual Key Attribution & Controls** — Added a `created_by` user attribution column and a `blacklisted_models` column for virtual key provider configs (#3672, #3653) - **Request Header Capture** — OTel and Maxim observability plugins capture `request_headers` by pattern, with wildcard support (e.g. `x-custom-*`); logging gained the same wildcard header capture (#4012, #3958) - **OTel Content Controls & Collectors** — New `disable_content_logging` option drops message/tool content from exported spans, plus support for multiple OTel collectors (#4064, #3894) - **xAI x_search** — Added xAI `x_search` tool support (#3976) - **URL Validation** — Added fetch URL validation with private-network configuration and link-local blocking (#3947, #3991) - **File Scheme Pricing URLs** — Pricing source URLs now accept the `file://` scheme for air-gapped and self-hosted deployments (#4045) - **Paginated Virtual Keys** — Virtual key fetching is paginated to handle deployments with very large numbers of keys (#3957) - **Client IP Resolution** — Resolve client IP from `X-Forwarded-For`/`X-Real-IP` headers - **SCIM Provisioning** — Added `attributeType`/`attributeValue` SCIM provisioning fields - **Helm/Config Schema** — Added `roles` RBAC governance config and `per_user_oauth` MCP auth to the Helm chart and config schema (#4004, #4009) - **Log Navigation UI** — Added a "View logs" menu item to customer, team, and virtual key tables, clickable links in log detail views, a customer detail sheet, and a reusable `BudgetDisplay` component (#4073, #4054, #4026, #4055) - **Faster First Paint** — Added an inline loading shell to `#root` before React mounts (#4063) - **Materialized View Alias** — Added an `alias` column to the materialized view with filter support (#4078) ## 🐞 Fixed - **Fetch URL IP Checks** — Hardened fetch URL IP checks against SSRF (#4092) - **Mantle Model Matching** — Broadened Mantle model matching to all `gpt` variants (#4091) - **Empty Thinking Blocks** — Strip thinking blocks when the signature is empty (#4079) - **OpenAI Stream Usage** — Removed usage from the `responses.created` event in the OpenAI stream (#4080) - **Prompt Cache Key** — Set the prompt cache key from the Anthropic integration (#4086) - **Upstream Failure Status** — Map upstream connection failures to 502 instead of 400 (#3929) (thanks [@chris-colinsky](https://github.com/chris-colinsky)!) - **Gemini Schema Constraints** — Accept numeric schema integer constraints for Gemini (#3994) (thanks [@yanhao98](https://github.com/yanhao98)!) - **Files Provider Param** — Accept the `?provider=` query param on `GET /v1/files` (#3971) (thanks [@alexef](https://github.com/alexef)!) - **Optional Batch Model** — Made the `model` field optional on `POST /v1/batches` (#3973) (thanks [@alexef](https://github.com/alexef)!) - **Helm Azure Config** — Added missing `azure_key_config` fields to the Helm schema (#3996) (thanks [@axelray-dev](https://github.com/axelray-dev)!) - **Text Completion Chunk Model** — Added the missing `Model` field to `TextCompletionChunkResponse` (#3970) (thanks [@kuishou68](https://github.com/kuishou68)!) - **MCP Inline stdio Env** — MCP stdio server configs accept inline environment variable assignments (#3861) (thanks [@Shushmitaaaa](https://github.com/Shushmitaaaa)!) - **Orphaned Tool Results** — Orphaned tool results in the OpenAI to Anthropic conversion flow are no longer rejected by the Anthropic API (#3919) - **Node Usage Reconciliation** — Added a monotonic `inc_number` log cursor so node usage reconciliation does not skip late async log writes (#3664) - **Bedrock Output Assessments** — Corrected the type of `outputAssessments` in Bedrock responses (#4028) - **Model Pool Pricing Reloads** — Preserve non-pricing model pool entries across pricing reloads (#3999) - **Ghost Node Reconciliation** — Replicate the VK hierarchy flow for ghost node reconciliation (#4088) - **VK Double Usage Counting** — Fixed double usage counting when creating a virtual key (#4070) - **Model Config Lifecycle** — Cascade deletes for model configs and removal of stale in-memory model configs (#4051, #4043) - **FTS Index Cap** — Reduced the FTS index `left()` cap from 800k to 250k chars to stay within the tsvector limit (#4057) - **Sync Worker Drift** — Reduced the sync worker ticker period to 5m to prevent threshold drift (#4023) - **Passthrough** — Fixed passthrough budgets, gated passthrough models per VK, model extraction for Azure passthrough, and restricted fallbacks/provider selection to the VK boundary (#3941, #3988, #3983, #3924) - **Provider Response Headers** — Strip provider response headers and add a content-type filter (#3955, #4024) - **Stream Handling** — Drain non-SSE stream readers and retry stale connections (#3956, #3967) - **Azure Claude** — Strip Azure diagnostic property for Claude models (#3925) - **Compat max_tokens** — Preserve chat `max_tokens` during param filtering (#3992) - **Raw Request Flag** — Removed the raw request flag from providers that don't support it (#4058) - **UI Fixes** — Standardized page container layout, virtual key model configs UI, and dashboard chart tooltips (#4046, #4052, #4044) ## 🔧 Maintenance - **Dependency Upgrades** — Bumped transitive `golang.org/x` dependencies (crypto, net, sys, text) for Docker Scout CVE remediation and `recharts` to 3.8.1; cascaded version bumps across all modules (#3900, #4003)

Summary
Adds wildcard pattern support to the logging headers configuration, allowing users to capture groups of headers by prefix (e.g.
x-custom-*) or all headers at once using*, rather than only exact header name matches.Changes
loggingHeaderMatchesPatternto handle exact matches, trailing wildcard (x-custom-*), and bare wildcard (*) patterns against incoming header namescaptureLoggingHeadersto iterate over all request headers and match each against configured patterns, replacing the previous single-key lookupType of change
Affected areas
How to test
Configure logging headers with a wildcard pattern such as
x-custom-*or*and send requests with matching headers. Verify that the captured headers appear in themetadatafield of log entries.Screenshots/Recordings
Before: Placeholder showed
X-Tenant-ID, X-Request-Source, X-Correlation-IDwith no mention of wildcard support.After: Placeholder shows
X-Tenant-ID, X-Request-Source, x-custom-*and the description explains exact names, prefix wildcards, and the bare*option.Breaking changes
Related issues
Security considerations
Using
*as a logging header pattern will capture all request headers, which may include sensitive values such asAuthorizationor session tokens. Users should be aware of the PII and secrets exposure risk when enabling broad wildcard patterns, and ensure log storage is appropriately access-controlled.Checklist
docs/contributing/README.mdand followed the guidelinesSummary by CodeRabbit
New Features
x-custom-*,*) as well as exact names.*) and prefix (prefix*) wildcards.x-bf-lh-prefix are always captured.Documentation